User-Driven Access Control: Rethinking Permission Granting in Modern Operating Systems

被引:78
作者
Roesner, Franziska [1 ]
Kohno, Tadayoshi [1 ]
Moshchuk, Alexander [3 ]
Parno, Bryan [3 ]
Wang, Helen J. [3 ]
Cowan, Crispin [2 ]
机构
[1] Univ Washington, Seattle, WA 98195 USA
[2] Microsoft, Redmond, WA USA
[3] Microsoft Res, Redmond, WA USA
来源
2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP) | 2012年
关键词
D O I
10.1109/SP.2012.24
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Modern client platforms, such as iOS, Android, Windows Phone, Windows 8, and web browsers, run each application in an isolated environment with limited privileges. A pressing open problem in such systems is how to allow users to grant applications access to user-owned resources, e. g., to privacy- and cost-sensitive devices like the camera or to user data residing in other applications. A key challenge is to enable such access in a way that is non-disruptive to users while still maintaining least-privilege restrictions on applications. In this paper, we take the approach of user-driven access control, whereby permission granting is built into existing user actions in the context of an application, rather than added as an afterthought via manifests or system prompts. To allow the system to precisely capture permission-granting intent in an application's context, we introduce access control gadgets (ACGs). Each user-owned resource exposes ACGs for applications to embed. The user's authentic UI interactions with an ACG grant the application permission to access the corresponding resource. Our prototyping and evaluation experience indicates that user-driven access control enables in-context, non-disruptive, and least-privilege permission granting on modern client platforms.
引用
收藏
页码:224 / 238
页数:15
相关论文
共 36 条
[1]  
ADOBE, 2008, US IN ACT REQ FLASH
[2]  
[Anonymous], 2011, USENIX SEC S
[3]  
[Anonymous], 2010, P NDSS
[4]  
[Anonymous], 2012, P 8 S US PRIV SEC AC
[5]  
[Anonymous], USENIX OSDI
[6]  
[Anonymous], ANDROID THREATS GETT
[7]  
APPLE, 2011, APP SANDB MAC APP ST
[8]  
APPLE, 2011, IOS4
[9]  
CHROMIUM, 2011, CHROMIUM SECURITY IS
[10]   A safety-oriented platform for Web applications [J].
Cox, Richard S. ;
Hansen, Jacob Gorm ;
Gribble, Steven D. ;
Levy, Henry M. .
2006 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2006, :350-+